Patch for Windows Defender 0-day could allow attackers to fill hard disk

by | Aug 2, 2026 | Technology

Patch for Windows Defender 0-day could allow attackers to fill hard disk

A security update Microsoft released on Wednesday addressed CVE-2026-50656, a zero-day vulnerability in the Microsoft Malware Protection Engine used by Windows Defender. The vulnerability, initially disclosed in June by a researcher operating under the pseudonym NightmareEclipse, permits remote attackers to gain administrative control of Windows 10 and Windows 11 systems even when real-time protection is disabled.

However, the researcher claimed on Thursday that the patch introduces new problems through its defense-in-depth additions. According to the analysis, modifications to mpengine.dll and functionality in SpyNet, Microsoft’s cloud-based service for reporting suspicious software, may enable attackers to exhaust available disk space on targeted machines. The researcher noted that while Defender typically enforces size restrictions on files written during scanning and quarantine operations, a specific exception exists related to Zone. Identifier alternate data streams, which the service caches without size limitations.

NightmareEclipse described a potential exploitation method using Server Message Block, the Windows file-sharing protocol. The attack would require a specially configured SMB server delivering a malicious file followed by an enormously sized alternate data stream. By halting responses to read requests while maintaining the connection, the server could cause Defender to lock files and exhaust disk space, degrading system performance and causing applications to crash randomly.

The disclosure reflects ongoing tensions between the researcher and Microsoft. The two parties have been in dispute since May, when NightmareEclipse claimed Microsoft silently patched a privately reported vulnerability. Subsequently, the researcher publicly released details and exploit code for multiple vulnerabilities ahead of Microsoft’s patch schedule. Microsoft condemned the approach as irresponsible disclosure and initially suggested potential legal action before backing away following public criticism.

Microsoft said it is investigating the newly reported issue. The publication was updated on July 13 to include the company’s response.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI